Praja Hakku

PRAJA HAKKU

The Journalism of Outrage

Investigate

WhatsApp trustee scam empties ₹50 lakh from a Hyderabad hospital

WhatsApp trustee scam empties ₹50 lakh from a Hyderabad hospital

Cyber fraudsters impersonating a trustee of a private charitable-trust hospital in Hyderabad cheated the institution of ₹50 lakh through WhatsApp instructions, according to reports published on 31 August 2026. The method was familiar in outline and devastating in detail: a trusted face on a phone screen, a finance manager who thought he was obeying a trustee, and a bank transfer that cleared before anyone verified the voice behind the photograph.

On 28 August 2026 the hospital’s general manager for finance received WhatsApp messages from an unknown number that used the trustee’s photograph as its display picture. The impersonator asked about trust bank balances and then instructed a transfer of ₹50 lakh to an account that, in one account of the case, was registered in Kerala. The manager submitted a letter to the hospital’s bank with a cheque number. The bank processed ₹50 lakh even though the cheque itself remained unsigned — a detail explained in reporting as a consequence of treating the hospital as a long-standing customer.

The next day the same impersonator demanded another ₹1 crore, this time to a different account. That second ask broke the pattern. The manager grew suspicious, called the real trustee, and heard a flat denial that any such request had been made. Only then did the institution understand that the first transfer had already left on a forged digital authority.

A complaint went to Hyderabad cybercrime police. A case was registered and the probe continues. The public facts available on 31 August do not yet name arrests, recovered amounts, or a closed charge sheet. They do establish the sequence: impersonation via WhatsApp, a ₹50 lakh outward remittance on an unsigned-cheque pathway, a failed attempt to extract a further ₹1 crore, and a formal cyber complaint.

The case is a warning written in institutional blood. Charitable-trust hospitals often combine high daily balances with lean verification cultures, especially when a “trustee” appears to speak with urgency. Display pictures are not identity documents. Cheque numbers in a covering letter are not substitutes for a signed instrument. A second account demand should have been a red flag before the first rupee moved; here it became the alarm after ₹50 lakh had already gone.

For other hospitals, temples, schools and trust-run colleges, the operational lesson is brutal and simple. Verify out-of-band. Call the known number, not the number that messaged. Treat any request to change beneficiary accounts as hostile until proven otherwise. Banks that process unsigned instruments for “relationship” reasons are part of the vulnerability surface, not outside it.

This cutting stays inside the reported facts: ₹50 lakh lost, a ₹1 crore second demand that failed, a Kerala-registered account mentioned in one report, an unsigned cheque that still moved money, and a live Hyderabad cybercrime investigation. It does not invent victim-hospital branding beyond the charitable-trust description, nor does it invent recovery figures that the 31 August reports do not provide.